CVE-2023-37198: Schneider Electric Struxureware Data Center Expert
High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages.
Affected products
- Schneider Electric Struxureware Data Center Expert: up to and including 7.9.3
Published 2023-07-12. Last modified 2026-06-17.